Dark Web Profile: Andariel
ID: ad7c6d74-ccf6-560c-a736-0d015f6cb4bf
STIX ID: report--ad7c6d74-ccf6-560c-a736-0d015f6cb4bf
Feed Name: SOCRadar Blog
Andariel is profiled as a North Korea–linked APT operating under the Reconnaissance General Bureau that blends state-directed espionage with financially motivated ransomware and cryptocurrency theft. The report outlines primary targets (defense, aerospace, nuclear, healthcare, finance), common initial access vectors (vulnerability exploitation, spear-phishing, watering holes), credential-focused lateral movement, data staging/exfiltration practices, notable malware families (Maui, DTrack, TigerRAT, etc.), and recommended mitigations such as patch management, MFA, network segmentation, EDR, and immutable backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
